Method: criteria, weights, scoring rules
Primary backbone (public destructive tests)
The durability baseline is anchored to Jameson Lopp’s multi-round destructive testing (heat, corrosion, crush) and the consolidated device table and reviews: jlopp.github.io/metal-bitcoin-storage-reviews. For historical context and the “Seedplate from Coinkite” cohort, see: Stress Test Round IV and for Keystone Tablet variants: Stress Test Round V.
Criteria & weights (fixed)
| Criterion | Weight | What increases the score | What decreases the score |
|---|---|---|---|
| Artifact Metadata & Privacy | 30% | Plain, un-numbered, minimally branded plates; no enforced seals; no QR/descriptor fields on the metal. | Unique serial numbers, numbered seals/covers, seed-name fields, collectible engravings, QR/descriptor on-plate. |
| Physical Robustness | 25% | Demonstrated survival under heat/corrosion/crush (preferably in Lopp tests), thick stainless or titanium, readable after stress. | Known weak modes (e.g., tile loss in heat, enclosure failure under crush), untested complex mechanisms. |
| Mechanical Simplicity | 15% | Single solid plate; minimal fasteners; no tiles/rails; nothing that jams or scatters parts. | Tile systems, multi-part cassettes, seal subsystems, capsule lockups, high part count. |
| Usability & Error Resistance | 10% | Clear 4-letter BIP39 grids, low cognitive load, fewer steps, fewer opportunities for transcription mistakes. | Word→index conversion steps, fiddly tile placement, multi-screw assembly, ambiguous recovery in degraded conditions. |
| Sovereign Ethos | 10% | Vendor-agnostic BIP39, minimal “ecosystem lock-in”, strong self-custody posture. | “Managed” flows centered on seals, branded dependency, or artifact identity features. |
| Flexibility / Use-case Fit | 5% | Supports multiple strategies (multi-location, multi-copy, multisig/shares) without adding metadata. | Over-specialization that forces extra metadata onto the artifact. |
| Cost / Deployability | 5% | Reasonable unit price enabling multiple independent backups. | Premium pricing that reduces redundancy or distribution options. |
Composite math (exact)
Composite = (Metadata×0.30) + (Robustness×0.25) + (Simplicity×0.15)
+ (Usability×0.10) + (Ethos×0.10) + (Flexibility×0.05) + (Cost×0.05)
Final ranking
Composite scores below are shown to two decimals (weighted sum) and rounded (integer) for quick scanning. Each device name links to its deep-dive section; external links are embedded in each deep dive.
| Rank | Device | Composite (exact) | Composite (rounded) |
|---|---|---|---|
| 1 | Coinkite SEEDPLATE (24 + Tiny 12) | 95.55 | 96 |
| 2 | Shift Crypto (BitBox) Steelwallet | 95.15 | 95 |
| 3 | CRYPTOTAG Zeus Starter Kit | 93.90 | 94 |
| 4 | Coinplate Alpha | 91.50 | 92 |
| 5 | BitBox Steelwallet Pro | 86.85 | 87 |
| 6 | Trezor Keep Metal (20/24) | 80.80 | 81 |
| 7 | SeedHammer II plates | 80.70 | 81 |
| 8 | Keystone Tablet | 75.55 | 76 |
| 9 | HODLR Shield (12/24) | 72.05 | 72 |
| 10 | Cryptosteel Cassette Solo | 71.00 | 71 |
Full score matrix (0–100 per criterion)
| Device | Metadata 30% |
Robustness 25% |
Simplicity 15% |
Usability 10% |
Ethos 10% |
Flex 5% |
Cost 5% |
Composite |
|---|---|---|---|---|---|---|---|---|
| Coinkite SEEDPLATE | 98 | 97 | 98 | 89 | 94 | 90 | 88 | 95.55 |
| BitBox Steelwallet | 98 | 97 | 96 | 89 | 93 | 92 | 86 | 95.15 |
| CRYPTOTAG Zeus | 97 | 98 | 95 | 86 | 92 | 90 | 75 | 93.90 |
| Coinplate Alpha | 88 | 96 | 94 | 90 | 92 | 92 | 84 | 91.50 |
| Steelwallet Pro | 80 | 94 | 88 | 87 | 92 | 95 | 70 | 86.85 |
| Trezor Keep Metal | 60 | 94 | 88 | 90 | 85 | 92 | 80 | 80.80 |
| SeedHammer II plates | 55 | 94 | 92 | 86 | 95 | 96 | 80 | 80.70 |
| Keystone Tablet | 60 | 75 | 84 | 86 | 88 | 90 | 86 | 75.55 |
| HODLR Shield | 30 | 95 | 88 | 88 | 88 | 92 | 78 | 72.05 |
| Cryptosteel Cassette | 45 | 78 | 82 | 85 | 88 | 90 | 78 | 71.00 |
Tier summary
Tier 1 — Clean plates (minimal artifact metadata; high survivability)
- Coinkite SEEDPLATE — no seals, no serials, simple punch plate (details).
- BitBox Steelwallet — Lopp-tested A-grade behavior in a simple two-plate form (details).
- CRYPTOTAG Zeus — titanium survivability with a small usability/cost trade (details).
- Coinplate Alpha — very strong physical construction; optional security labels are the main metadata caveat (details).
Tier 2 — Strong tools with explicit trade-offs (seals / metadata / specialization)
- Steelwallet Pro — reusable; includes tamper-evident sticker as part of the closure model (details).
- Trezor Keep Metal — robust; includes security seals in the standard workflow (details).
- SeedHammer plates — extreme multisig capability, but descriptor + QR can be embedded onto the artifact by design (details).
Tier 3 — Dominated under the artifact-purity model (identity surfaces / weak modes / part complexity)
- Keystone Tablet — tile systems introduce failure modes; Lopp tests show strong asymmetry by variant (details).
- HODLR Shield — uniquely identified editions and uniquely numbered covers create linkability primitives (details).
- Cryptosteel Cassette — crush weakness in Lopp tests plus seal subsystem and high part-count (details).
Device deep dives (all details)
Each section includes a scorecard, rationale, and inline links to official pages and test references.
1) Coinkite SEEDPLATE (24 Words + Tiny 12)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 98 | No serials; no enforced seals; no descriptor/QR on the plate. Minimal identity surface on the artifact (Coinkite SEEDPLATE). |
| Physical Robustness (25%) | 97 | Lopp’s Seedplate test shows no data loss under heat/corrosion/crush (review). |
| Mechanical Simplicity (15%) | 98 | Single plate; no tiles; no enclosure that can jam. |
| Usability & Error Resistance (10%) | 89 | Manual center-punch on a 4-letter BIP39 grid; straightforward but still manual. |
| Sovereign Ethos (10%) | 94 | Vendor-agnostic BIP39 backup with minimal “managed” workflow and no semantic bloat on metal. |
| Flexibility / Use-case Fit (5%) | 90 | Works for single-sig and as a replicated artifact across multi-location / multisig strategies. |
| Cost / Deployability (5%) | 88 | Low enough to deploy multiple copies (pricing). |
Why it ranks #1
2) Shift Crypto (BitBox) Steelwallet (non-Pro)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 98 | Plain plates with no enforced seals or identifiers (shop page). |
| Physical Robustness (25%) | 97 | Lopp review reports no data loss in heat/corrosion/crush for Steelwallet (review). |
| Mechanical Simplicity (15%) | 96 | Two plates and punch; minimal part-count compared to tile systems. |
| Usability & Error Resistance (10%) | 89 | Clear instruction flow and familiar 4-letter BIP39 pattern (features). |
| Sovereign Ethos (10%) | 93 | Vendor-agnostic seed backup, minimal workflow ceremony (overview). |
| Flexibility / Use-case Fit (5%) | 92 | Two-plate form is inherently redundancy-friendly; supports multi-copy / multi-location distribution. |
| Cost / Deployability (5%) | 86 | Moderate unit cost; still feasible for multiple independent backups (pricing). |
Why it ranks #2 (near tie with #1)
3) CRYPTOTAG Zeus Starter Kit (titanium)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 97 | No enforced seals/serials described; artifact is not designed around linkability (Lopp review). |
| Physical Robustness (25%) | 98 | Titanium and strong performance in Lopp’s heat/corrosion/crush testing (review). |
| Mechanical Simplicity (15%) | 95 | Simple plate workflow; minimal parts; no tile matrix. |
| Usability & Error Resistance (10%) | 86 | Word→index mapping adds cognitive steps versus 4-letter punch grids (see workflow in product docs). |
| Sovereign Ethos (10%) | 92 | BIP39-compatible across wallets; not tied to a coordinator or descriptor scheme. |
| Flexibility / Use-case Fit (5%) | 90 | Strong for long-term seed survivability; suited to multi-copy distribution. |
| Cost / Deployability (5%) | 75 | Premium titanium pricing can reduce redundancy per budget (pricing). |
Primary trade-off
4) Coinplate Alpha
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 88 | Plate is clean; kits often include tamper-evident “security labels” as a feature (example kit listing). |
| Physical Robustness (25%) | 96 | Lopp review documents strong performance; 5mm AISI 304 plates and bolts (review; specs). |
| Mechanical Simplicity (15%) | 94 | Two plates + bolts; no tile system. Slightly more hardware than single plates. |
| Usability & Error Resistance (10%) | 90 | Clear layout; bolted sandwich improves survivability while remaining readable (layout). |
| Sovereign Ethos (10%) | 92 | BIP39-first and vendor-agnostic; no descriptor/QR on artifact. |
| Flexibility / Use-case Fit (5%) | 92 | Supports replicated backups and multi-location storage; value packs exist (shop). |
| Cost / Deployability (5%) | 84 | Moderate price for robustness; better value than many premium titanium kits (pricing). |
Key nuance
5) BitBox Steelwallet Pro
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 80 | Includes a tamper-evident sticker as part of the closure model (shop page). Some third-party reviews describe the sticker as numbered (Blocktrainer). |
| Physical Robustness (25%) | 94 | Thick stainless casing designed for fire/water/impact (specs). Not in Lopp’s dataset; robustness score reflects design/material expectations rather than a public destructive series. |
| Mechanical Simplicity (15%) | 88 | Tile + rail + casing introduces more failure points than a punch plate. |
| Usability & Error Resistance (10%) | 87 | Avoids punching errors but introduces tile handling complexity; reusable design is the main advantage. |
| Sovereign Ethos (10%) | 92 | Still vendor-agnostic BIP39 storage; no descriptor/QR on artifact. |
| Flexibility / Use-case Fit (5%) | 95 | High flexibility due to reusability (product description). |
| Cost / Deployability (5%) | 70 | Premium cost reduces easy multi-copy deployment (BitBox shop pricing list). |
Why it beats most “capsule/tile” systems but not the top plates
6) Trezor Keep Metal (20/24 variants)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 60 | Security seals are included as part of the standard kit (“What’s in the box” includes “Security seals”) (product page). |
| Physical Robustness (25%) | 94 | AISI 304 stainless with black surface treatment; marketed as waterproof and corrosion resistant (product details). Not in Lopp’s dataset. |
| Mechanical Simplicity (15%) | 88 | More assembly and enclosure mechanics than flat plates; still simpler than many tile cassettes. |
| Usability & Error Resistance (10%) | 90 | Four-letter entry system and guided kit approach (workflow). |
| Sovereign Ethos (10%) | 85 | BIP39/backup compatible across wallets, but positioned as a branded system within Trezor’s ecosystem pages. |
| Flexibility / Use-case Fit (5%) | 92 | Multiple word-length variants and compatibility claims (guide). |
| Cost / Deployability (5%) | 80 | Mid pricing; deployable in multiples, but less efficiently than cheaper plates. |
Primary reason it ranks below the top tier
7) SeedHammer II plates (backup plates)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 55 | SeedHammer plates can embed descriptor parts and QR codes on metal to enable fast recovery (metal plates article), which is structurally metadata-rich compared to seed-only plates. Seed-only mode exists (FAQ). |
| Physical Robustness (25%) | 94 | 316L “marine grade” stainless and thick plates are chosen for harsh conditions (material rationale). Not in Lopp’s dataset. |
| Mechanical Simplicity (15%) | 92 | The plate artifact is simple; complexity is primarily in the backup format and optional QR use. |
| Usability & Error Resistance (10%) | 86 | High speed recovery by scanning QR shares into coordinators like Sparrow is a design goal (QR discussion). |
| Sovereign Ethos (10%) | 95 | Strong multisig focus; avoids dependence on digital descriptor storage by embedding descriptor parts in steel (scheme). |
| Flexibility / Use-case Fit (5%) | 96 | Designed around quorum recovery in multisig setups (partitioning). |
| Cost / Deployability (5%) | 80 | Plates themselves are deployable; full workflow often assumes access to the SeedHammer engraver stack. |
Core trade-off: capability vs artifact purity
8) Keystone Tablet (Tablet / Tablet Plus / Tablet Punch family)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 60 | Includes “security seal stickers” / “tamper-proof stickers” in standard box contents (Tablet; Tablet Plus). |
| Physical Robustness (25%) | 75 | Variant-dependent: Tablet Plus and Punch have different Lopp grades (see master table and Round V). |
| Mechanical Simplicity (15%) | 84 | Tile systems + multiple screws increase failure surface compared to punch plates. |
| Usability & Error Resistance (10%) | 86 | Readable tiles, but assembly and long-term handling are more error-prone than punch grids. |
| Sovereign Ethos (10%) | 88 | Wallet-agnostic backup; not descriptor-heavy by default. |
| Flexibility / Use-case Fit (5%) | 90 | Supports multiple word lengths and setups; reusability depends on variant (Plus). |
| Cost / Deployability (5%) | 86 | Often priced to enable multiple deployments, but with survivability caveats by variant. |
Variant note (important)
9) HODLR Shield (12/24 variants)
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 30 | Bitcoin Edition is “laser-marked with the last mined Bitcoin block … and a unique serial number” (official description). Shield variants can include “uniquely numbered tamper-evident covers” (Stealth 24). |
| Physical Robustness (25%) | 95 | Engineered for high physical protection; marketing emphasizes pressure-tightening behavior and high resistance (Stealth page). |
| Mechanical Simplicity (15%) | 88 | More moving pieces and sealing elements than a simple plate. |
| Usability & Error Resistance (10%) | 88 | Four-letter marking workflow is familiar; packaging includes aids and protocols (how it works). |
| Sovereign Ethos (10%) | 88 | Self-custody aligned, but “collector artifact” identity features run against a strict unlinkability posture. |
| Flexibility / Use-case Fit (5%) | 92 | Supports multiple backup setups including multi-share protocols in their “backup protocol” guides (Stealth page). |
| Cost / Deployability (5%) | 78 | Premium pricing can reduce multi-copy distribution (see pricing on product pages). |
Why it ranks low despite strong physical engineering
10) Cryptosteel Cassette Solo
| Criterion | Score | Notes |
|---|---|---|
| Artifact Metadata & Privacy (30%) | 45 | Cassette Solo includes “four tamper-evident security seals with composite wire” as part of the set (official). PSW-97 style seals are commonly numbered (PSW-97). |
| Physical Robustness (25%) | 78 | Lopp grades the Cassette as B overall with a D in crush (critical) (master table; review). |
| Mechanical Simplicity (15%) | 82 | Tile cassette + seals introduces many small parts and failure points. |
| Usability & Error Resistance (10%) | 85 | Readable 4-letter tiles, but assembly and maintenance are more tedious than punch plates (how it works). |
| Sovereign Ethos (10%) | 88 | Vendor-agnostic BIP39 approach; no descriptor/QR on artifact by default. |
| Flexibility / Use-case Fit (5%) | 90 | Supports multiple wallets and setups; still dominated by simpler plates under this model. |
| Cost / Deployability (5%) | 78 | Mid-to-premium price without corresponding crush survivability compared to A-grade plates. |